US2025338116A1PendingUtilityA1
Key management method and apparatus, device, and storage medium
Assignee: BEIJING XIAOMI MOBILE SOFTWARE CO LTDPriority: May 13, 2022Filed: May 13, 2022Published: Oct 30, 2025
Est. expiryMay 13, 2042(~15.8 yrs left)· nominal 20-yr term from priority
H04W 8/005H04W 12/041H04W 12/0433H04W 12/72H04W 12/043H04W 12/06H04W 12/08H04W 12/0431
50
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A key management method, includes: receiving, by a proxy entity in a service network, an application key confirmation request sent by an anchor function network element (AAnF) of authentication and key management for applications (AKMA) in a home network.
Claims
exact text as granted — not AI-modified1 . A key management method, the method comprising:
receiving, by a proxy entity in a service network, an application key confirmation request sent by an anchor function network element (AAnF) of authentication and key management for applications (AKMA) in a home network.
2 . The method of claim 1 , wherein the application key confirmation request comprises at least one of:
AKMA application key; expiration time of the AKMA application key; an AF identifier of an application function (AF) in the home network; an AKMA key identifier of a terminal; or a subscription permanent identifier (SUPI) of the terminal.
3 . The method of claim 1 , wherein the application key confirmation request is sent by the AAnF to the proxy entity in case that a service network identifier of a terminal is different from a home network identifier.
4 . The method of claim 1 , further comprising:
sending, by the proxy entity, an application key confirmation response to the AAnF; storing, by the proxy entity, the application key confirmation request.
5 .- 6 . (canceled)
7 . A key management method, applied in a roaming scenario, the method comprising:
receiving, by an application function (AF) in a home network, a service network identifier and an AKMA key identifier sent by a terminal; sending, by the AF, an application key acquisition request to an AAnF in the home network, wherein the application key acquisition request carries the service network identifier, and the service network identifier is used to trigger the AAnF to send an application key confirmation request to a proxy entity in a service network in case that the service network identifier of the terminal is different from a home network identifier; and receiving, by the AF, an application key acquisition response fed back from the AAnF, wherein the application key acquisition response comprises AKMA application key information of the AF.
8 . The method of claim 7 , wherein the AKMA application key information comprises at least one of:
AKMA application key; expiration time of the AKMA application key; or SUPI of the terminal.
9 . The method of claim 7 , wherein sending, by the AF, the application key acquisition request to the AAnF in the home network comprises at least one of:
sending, by the AF, a first application key acquisition request to the AAnF in case that the AF requires terminal identification; or sending, by the AF, a second application key acquisition request to the AAnF in the home network in case that the AF in the home network does not require terminal identification.
10 . The method of claim 9 , wherein the first application key acquisition request or the second application key acquisition request comprises at least one of:
an AKMA key identifier of the terminal; or an AF identifier of the AF in the home network.
11 . The method of claim 10 , wherein the first application key acquisition request or the second application key acquisition request comprises the AKMA key identifier and the service network identifier;
the AKMA key identifier carries the service network identifier; or the first application key acquisition request or the second application key acquisition request carries the service network identifier through a separate field.
12 .- 14 . (canceled)
15 . The method of claim 9 , wherein whether the AF requires the terminal identification is indicated by a policy in the AF.
16 . The method of claim 7 , further comprising at least one of:
receiving, by the AF, an error response fed back from the AAnF, and sending the error response to the terminal, wherein the error response is sent in case that the AKMA key of the terminal is not stored in the AAnF; or receiving, by the AF, an application session establishment request sent by the terminal, and feeding back an application session establishment response to the terminal, wherein the application session establishment request carries the service network identifiers.
17 . The method of claim 7 , further comprising:
discovering, by the AF, the AAnF through NRF in the home network.
18 . (canceled)
19 . The method of claim 16 , wherein
the application session establishment request comprises an AKMA key identifier of AKMA, wherein the AKMA key identifier carries the service network identifier; or the application session establishment request comprises the AKMA key identifier and the service network identifier; wherein, the AKMA key identifier is an identifier of an AKMA key of the terminal.
20 . The method of claim 16 , further comprising:
feeding back, by the AF, rejection information for application session to the terminal in case of receiving an error response fed back from the AAnF, wherein the rejection information comprises a response failure reason.
21 . A key management method according to claim 7 , the method comprising:
receiving, by the AAnF in the home network, the application key acquisition request sent by the AF in the home network, wherein the application key acquisition request carries the service network identifier; generating, by the AAnF in the home network, an AKMA application key of the AF based on an AKMA key of the terminal; feeding back, by the AAnF in the home network, the application key acquisition response to the AF, wherein the application key acquisition response comprises the AKMA application key information of the AF; and sending, by the AAnF in the home network, the application key confirmation request to the proxy entity in a the service network.
22 . The method of claim 21 , wherein receiving, by the AAnF in the home network, the application key acquisition request sent by the AF in the home network comprises at least one of:
receiving, by the AAnF in the home network, a first application key acquisition request sent by the AF, wherein the first application key acquisition request is used to indicate that the AF requires terminal identification; or receiving, by the AAnF in the home network, a second application key acquisition request sent by the AF, wherein the second application key acquisition request is used to indicate that the AF does not require terminal identification, wherein the AKMA application key information fed back from the AAnF does not comprise SUPI of the terminal in case that the AAnF receives the second application key acquisition request.
23 .- 24 . (canceled)
25 . The method of claim 21 , further comprising:
determining that the AAnF provides services to the AF and a proxy entity in the service network based on authorization information or policy, wherein the authorization information or policy is provided by a local policy or NRF in the home network.
26 . (canceled)
27 . The method of any of claim 21 , wherein sending the application key confirmation request to the proxy entity in the service network comprises:
sending the application key confirmation request to the proxy entity in case that a service network identifier of the terminal is different from a home network identifier; wherein the method further comprises: receiving an application key confirmation response sent by the proxy entity.
28 .- 29 . (canceled)
30 . The method of claim 21 , further comprising:
discovering the proxy entity in the-network elements of the service network through an NRF in the service network and the home network, in case that the service network identifier of the terminal is different from the home network identifier.
31 . A key management method, applied in a roaming scenario, and performed by a terminal, the method comprising:
sending a service network identifier and an AKMA key identifier to an application function (AF) in a home network, wherein the service network identifier is used to trigger an AAnF in the home network to send an application key confirmation request to a proxy entity in a service network in case that the service network identifier of the terminal is different from a home network identifier, and the AKMA key identifier is an identifier of an AKMA key of the terminal.
32 .- 40 . (canceled)Join the waitlist — get patent alerts
Track US2025338116A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.